CVE-2021-1578
published 2021-08-25CVE-2021-1578: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller…
PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.97%
78.3th percentile
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | — | — |
| cisco | application_policy_infrastructure_controller | 5.0 – 5.1\(3e\) | — |
| cisco | cisco_application_policy_infrastructure_controller | — | — |
| cisco | cloud_application_policy_infrastructure_controller | — | — |
| cisco | cloud_application_policy_infrastructure_controller | 5.0 – 5.1\(3e\) | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for non-privileged MSO credential usage sending API requests to APIC or Cloud APIC devices that result in Administrator-level privilege escalation ↗
- →Alert on any API responses from APIC/Cloud APIC that return or grant Administrator credentials to sessions that originated from non-privileged MSO accounts ↗
- ·The vulnerability is caused by an improper policy default setting on APIC/Cloud APIC; review and harden default API endpoint policies to restrict privilege escalation paths from MSO-sourced requests ↗
- ·There are no workarounds available; patching via Cisco software updates is the only remediation (tracked under Bug ID CSCvw57550) ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
vendor_cisco·2021-08-25·CVSS 8.8
CVE-2021-1578 [HIGH] CWE-636 Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device.
This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.
Cisco has released software updates that address this vulner
Red Hat
kernel: infinite loop in set_memory_region_test in arch/x86/kvm/svm/svm.c for certain nested page faults
vendor_redhat·2020-04-21·CVSS 5.5
CVE-2020-36310 [MEDIUM] CWE-835 kernel: infinite loop in set_memory_region_test in arch/x86/kvm/svm/svm.c for certain nested page faults
kernel: infinite loop in set_memory_region_test in arch/x86/kvm/svm/svm.c for certain nested page faults
An issue was discovered in the Linux kernel before 5.8. arch/x86/kvm/svm/svm.c allows a set_memory_region_test infinite loop for certain nested page faults, aka CID-e72436bc3a52.
A flaw was found in the Linux kernel. A nested page fault is created when an address does not have a memslot associated to it. The highest threat from this vulnerability is to system availability. This flaw can be triggered using a malformed Virtual Machine. When triggered this bug will lead to the user-space component of KVM to freeze.
Statement: Red Hat Product Security does not consider this to be a vulnerability. This issue has addressed as a regular bug in the errata RHSA-2021:2185 and RHSA-2021:1578. T
Cisco
Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2021-1578 Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
CVE-2021-1578: Cisco Application Policy Infrastructure Controller Privilege Escalation Vulnerability
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device. Cisco has released software updates that addres
GHSA
GHSA-9fcm-298r-cw5q: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Cont
ghsa_unreviewed·2022-05-24
CVE-2021-1578 [HIGH] CWE-755 GHSA-9fcm-298r-cw5q: A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Cont
A vulnerability in an API endpoint of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Application Policy Infrastructure Controller (Cloud APIC) could allow an authenticated, remote attacker to elevate privileges to Administrator on an affected device. This vulnerability is due to an improper policy default setting. An attacker could exploit this vulnerability by using a non-privileged credential for Cisco ACI Multi-Site Orchestrator (MSO) to send a specific API request to a managed Cisco APIC or Cloud APIC device. A successful exploit could allow the attacker to obtain Administrator credentials on the affected device.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-25
Published